5.8
CVSSv2

CVE-2020-35738

Published: 28/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 4.2 | Exploitability Score: 1.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases up to and including 5.3.2, which are also affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wavpack wavpack 5.3.0

debian debian linux 9.0

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #978548 wavpack: CVE-2020-35738 Package: src:wavpack; Maintainer for src:wavpack is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 28 Dec 2020 14:09:02 UTC Severity: important Tags: security, upstream Found ...
WavPack 530 has an out-of-bounds write in WavpackPackSamples in pack_utilsc because of an integer overflow in a malloc argument ...